SUBJECT PROFILE
The BlueNoroff/UNC1069 sub-unit of Lazarus executed the most significant npm supply chain attack of 2026 on March 30-31, poisoning the axios JavaScript package (~100M weekly downloads, present in ~80% of cloud environments) by socially engineering the lead maintainer to steal a long-lived npm access token and publish two malicious versions injecting the WAVESHAPER.V2 RAT (also tracked as SILKBELL by GTIG). The attack was contained in roughly three hours but generated ~600,000 poisoned downloads; OpenAI's macOS app-signing pipeline was exposed, forcing full code-signing certificate rotation. CISA issued an advisory on April 20, 2026, and attribution was confirmed by Microsoft (Sapphire Sleet), Google GTIG (UNC1069), and ThreatBook (Lazarus) independently.
Financial theft to fund DPRK regime; cryptocurrency exchange targeting; supply chain compromise for broad downstream access and credential harvesting
OPERATIONAL HISTORY
npm maintainer account takeover via social engineering (fake Calendly/Zoom invitations), long-lived npm token theft post-RAT deployment, postinstall lifecycle hook abuse, malicious transitive dependency injection (plain-crypto-js), cross-platform payload delivery (Windows PowerShell, macOS Mach-O NukeSped, Linux Python), WAVESHAPER/SILKBELL RAT, IE8/WinXP user-agent fingerprint (cross-campaign BlueNoroff indicator), AI-generated deepfakes in live video calls, cryptocurrency executive targeting via LinkedIn
KNOWN INFRASTRUCTURE
sfrclak[.]com C2 domain; 142.11.206.73 (same /18 netblock as 3 confirmed Lazarus IPs); plain-crypto-js@4.2.1 malicious npm package; attacker-controlled ProtonMail for maintainer account takeover; Quickpacket/Routerhosting/Hostwinds VPS infrastructure (historical BlueNoroff pattern)